About Course

The Certified Application Security Engineer (CASE) focuses on secure application software development processes. It is a, hands-on, comprehensive application security course that will help you create a secure application software. This course encompasses security activities involved in all phases of the Secure Software Development Lifecycle (SDLC): planning, creating, testing, and deploying an application

Application Security: the Current and NEXT BIG THING

For most organizations, software and applications determine their success. However, expedition, duplication, and penny-pinching take centrestage with security taking a backseat or is not present at all. An insecure or vulnerable application places these businesses at risk.

It is quite clear that application security still has a long way to go! Do you belong to the pack that follows unsafe coding and deployment practices? Are you one of the 21 Million, putting the security of the software or web application at risk, resulting with a catastrophic loss?

  • 1.8 Billion Active Websites Managed by 21 Million Developers Globally One of the Largest Economies – $5.6 Trillion by 2021
  • 3.5 Billion Active Users Making the Largest Platform For Identity and Financial Theft
  • Average of 19 Vulnerabilities Found Per Day Over 50% Termed Vulnerable 64% of Top 1 Million Alexa Websites Are Vulnerable

Security Risk Not Limited to only Web Applications

Many globally recognizable retail outlets have dealt with enormous data breaches recently because they ignored application security.

Billion-dollar companies with global footprints have faced massive data leakage, including their customers’ and employees’ personal and financial information, because their applications were faulty.

Retail giants like Forever 21, GameStop, Panera Bread, Sonic, KMart, and Hudson Bay (Saks Fifth Avenue) are a few on the list of retailers with thousands of outlets that used POS machines or payment gateways that allegedly resulted in information theft. There are many more modern, digital platforms like Uber, Yahoo, Dropbox, Adobe, LinkedIn, and Tumblr who also faced similar breaches, owing to the same reason – lack of application security.

Java

Java Based Applications: The Most Popular and Yet the Most Vulnerable?

According to the 2017 State of Software Security Report, nearly 90% of Java applications contain one or more vulnerable component, making them ideal breach points for hostile attackers. Although Java has come a long way from its development in 1995, cyber crime has also spread, reaching epidemic levels, increasing the need for secure Java developers, regardless of whether they’re creating a new program or upgrading an old one.

Attaining the Certified Application Security Engineer

CASE allows application developers and testers to demonstrate their mastery of the knowledge and skills required to handle common application software security vulnerabilities.

  • Exam Title: Certified Application Security Engineer
  • Number of Questions: 50
  • Test Duration: 2 Hours
  • Test Format: Multiple Choice
  • Availability: EC-Council Exam Portal

Show More

What Will You Learn?

  • In-depth understanding of secure SDLC and secure SDLC models
  • Knowledge of OWASP Top 10, threat modelling, SAST and DAST
  • Capturing security requirements of an application in development
  • Performing manual and automated code review of application
  • Driving development of a holistic application security program
  • Working in teams to improve security posture
  • Defining, maintaining, and enforcing application security best practices
  • Conducting application security testing for web applications to assess the vulnerabilities
  • Rating the severity of defects and publishing comprehensive reports, detailing associated risks and mitigations
  • Following secure coding standards that are based on industry-accepted best practices such as
  • OWASP Guide, or CERT Secure Coding to address common coding vulnerabilities.
  • Creating a software source code review process that is a part of the development cycles (SDLC, Agile, CI/CD)
  • Application security scanning technologies such as AppScan, Fortify, WebInspect, static application security testing (SAST), dynamic application security testing (DAST), single sign on, and encryption

Course Content

Module 01: Understanding Application Security, Threats, and Attacks

Module 02: Security Requirements Gathering

Module 03: Secure Application Design and Architecture

Module 04: Secure Coding Practices for Input Validation

Module 05: Secure Coding Practices for Authentication and Authorization

Module 06: Secure Coding Practices for Cryptography

Module 07: Secure Coding Practices for Session Management

Module 08: Secure Coding Practices for Error Handling

Module 09: Static and Dynamic Application Security Testing (SAST & DAST)

Module 10: Secure Deployment and Maintenance

Student Ratings & Reviews

5.0
Total 3 Ratings
5
3 Ratings
4
0 Rating
3
0 Rating
2
0 Rating
1
0 Rating
7 months ago
Informative, engaging, practical. The course delivers essential insights for those aiming to enhance their online marketing capabilities.
7 months ago
Engaging, practical, essential. The course equips learners to excel in online marketing strategies effectively and efficiently
7 months ago
Dynamic, practical, transformative. The course empowers learners to master effective online marketing strategies with confidence and clarity.